Somebody is running a massive bot attack against various support forums. See for example:
https://www.drupal.org/forum/support/before-you-start

They are coming in faster than I am able to report it as spam. They are get around the basic flooding protection (I assume they use a botnet to produce new users and unique IP-adresses.

I am reporting here rather than marking each individual instance as spam.

CommentFileSizeAuthor
#15 Thatsalot.jpg125.93 KBgobinathm
#12 img.jpg143.64 KBgobinathm

Comments

gisle created an issue. See original summary.

jaypan’s picture

It's insanity. What I don't understand is how they can keep posting even after being marked as spammers - isn't that the whole point of marking someone as a spammer?

killes@www.drop.org’s picture

Blocking works better I guess.

There may have been changes to the way the spam prevention works.

Blocked a few, deleted a few 100 posts...

jaypan’s picture

I'm still seeing a bunch of posts in at least the module development forum and the theme forum. And the Upgrading Drupal forum looks full as well.

gisle’s picture

Massive spam remains here:
https://www.drupal.org/forum/support/theme-development

At least one spam message remains in:
https://www.drupal.org/forum/support/before-you-start
https://www.drupal.org/forum/support/upgrading-drupal

I notice that the spammer accounts are now blocked, but that the spam is still published. Why don't you use the option that unpublishes and/or deletes content published by that account at the same time?

Edit: It seems that all has been deleted now.

killes@www.drop.org’s picture

I think I got them all now.

There used to be a snippet in settings.php that would disallow any posting of Korean characters. I guess that needs to be put in again. I am not able to do spam-sitting d.o on a regular basis again.

jaypan’s picture

I am not able to do spam-sitting d.o on a regular basis again.

Looks like no one is. We were getting spammed for 24 hours straight, even though at least two of us were reporting them (count based on this thread).

jaypan’s picture

And there it goes again. I just reported some more.

avpaderno’s picture

I delete all the spam I found, including some old unpublished posts.

jaypan’s picture

They're baaaaack....
I've given up on marking spammers as spammers though - it seems to have no effect. They just keep spamming.

gobinathm’s picture

Priority: Normal » Major

Bumping the priority ..

May be its time to think about better spam prevention solution.

gobinathm’s picture

Project: Drupal.org site moderators » Drupal.org infrastructure
Component: Spam » Blocked IPs
StatusFileSize
new143.64 KB

Definitely the spam prevention is not working. I marked the user as spammer. After that, this user was able to create spam posts.

https://www.drupal.org/user/3572483/track

SPAMMER

Moving issue to Infrastructure Queue.

b_man’s picture

Thanks for the reports, we were/are under a pretty heavy spam attack (and as you mentioned it's been going on for a while) and have been making adjustments within our current tool set to mitigate it as much as possible.

The main reason reporting someone as a spammer doesn't stop them from posting (though maybe we should consider changing this slightly) is because in the past it has been used as a weapon to try to silence someone during a debate, where that person had valid but opposing views. We want to ensure that our anti-spam tools can’t be used abusively.

Thanks everyone for your help in the spam fight.

jaypan’s picture

The main reason reporting someone as a spammer doesn't stop them from posting (though maybe we should consider changing this slightly) is because in the past it has been used as a weapon to try to silence someone during a debate, where that person had valid but opposing views. We want to ensure that our anti-spam tools can’t be used abusively.

I can understand that, but I think two things:

1) If someone does that, they should be severely reprimanded for abuse of the system. No one does that accidentally, it takes effort to mark someone as a spammer, and they can unmark them as well.

2) If someone is marked as a spammer, maybe they shouldn't be blocked from posting altogether, but rather throttled (six posts an hour or something)

gobinathm’s picture

StatusFileSize
new125.93 KB

Thats a lot of spam post by this user
https://www.drupal.org/user/3572884. Its clear that this user was a super spammer, i blocked the account instead of just reporting as spammer.

posted around 500+ junk forum posts in < 2 hours. Definitely its a LOT & automation.

A Lot

I don't read korean, but i was able to clearly make that judgement with help of translation tools

jaypan’s picture

I don't read korean, but i was able to clearly make that judgement with help of translation tools

It was pretty clear they were a spammer without a translation tool!

drumm’s picture

Its clear that this user was a super spammer, i blocked the account instead of just reporting as spammer.

gobinathm - yes, blocking is exactly what you should be doing as a webmaster. Reporting as spam is only meant to alert webmasters to probable spam. (There are some mis-reports of spam.) Webmasters are responsible for reviewing posts marked as spam and taking action.

drumm’s picture

We now have Akismet blocking spam.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.